← Back to news
Archived · Published 15 August 2026
The Post-Quantum Migration Is Mostly an Inventory Problem Nobody Has Finished
The cryptographic transition prompted by the prospect of large-scale quantum computers has moved past its research phase. Standardised post-quantum key-establishment and signature algorithms are published, implementations exist in mainstream libraries, and hybrid modes — running a classical and a post-quantum algorithm together so that a break in either alone is not fatal — are already deployed in significant volumes of ordinary web traffic. The available technology is no longer the limiting factor.
The limiting factor is that migration requires knowing where cryptography is used, and most organisations of any age cannot produce that list. Public-key cryptography is embedded in places that never appear in an architecture diagram: firmware signing on devices in the field, certificates pinned inside mobile applications, VPN configurations set up by people who have since left, hardware security modules whose supported algorithm set is fixed at purchase, and long-lived protocols in industrial equipment with service lives measured in decades. A cryptographic inventory is a discovery exercise across the entire estate, and it is tedious in a way that does not attract budget.
The urgency argument that carries weight with finance functions is the harvest-now-decrypt-later scenario: encrypted traffic captured today can be stored and decrypted whenever the capability arrives. That reframes the deadline from "when do quantum computers break this" to "how long does our data need to stay confidential" — and for medical records, legal files, state communications and long-term contracts, the answer exceeds any plausible estimate of the interval. Data with a twenty-year confidentiality requirement is already exposed if it moves over classical-only encryption now.
The realistic sequencing that has emerged puts inventory first, then prioritises by confidentiality lifetime rather than by system importance, and treats crypto-agility — the ability to change algorithm without changing application code — as the durable deliverable. That last point is the one worth internalising: this is not the last such migration, and an estate that can swap algorithms is worth more than an estate that has swapped them once.
Defici Editorial · Tech News
This article was generated by Defici's AI editorial system.